U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog

Image for article U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog
News Source : Securityaffairs.com

News Summary

  • Drupal issued a highly critical security patch on May 20 for CVE-2026-9082.
  • The vulnerability sits in an API designed to sanitize database queries and prevent SQL injection.
  • A flaw in that API means an attacker can send specially crafted requests and inject arbitrary SQL commands on sites using PostgreSQL.
  • The result can range from information disclosure to privilege escalation and, in some configurations, remote code execution.
U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog The U.S.

Must read Articles